Executive brief
Tenda TX9 Pro routers are affected by a security flaw in the web management interface. By sending a specially crafted network request to change a device name, an attacker can cause the router to crash or become unresponsive. This results in a denial of service, disrupting internet connectivity for all connected users and requiring a manual restart to restore operations.
Technical details
A stack-based buffer overflow exists in the Tenda TX9 Pro V22.03.02.20 firmware within the 'httpd' binary. The vulnerability is located in the 'update_dev_name' function (called by 'sub_425964') inside 'libtd_server.so'. The root cause is improper bounds checking when converting the 'devName' POST parameter from GB2312 to UTF-8 using the 'gb2312_2_utf8' function. A remote attacker can exploit this by sending a long string in the 'devName' parameter to the '/goform/SetOnlineDevName' endpoint, leading to a crash of the web service or the entire device.
Affected products
- Tenda TX9 Pro V22.03.02.20
Timeline
- 2024-10-21: other: Initial vulnerability report and PoC published on Gitee
- 2026-07-20: disclosed: CVE published to NVD dataset